9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2018-1821
Operational Decision Management General
7.1
HIGH
EPSS
23.8%
2018 1 PoC

IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150170.

CVE-2018-4035
Clean My Mac General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

The CleanMyMac X software contains an exploitable privilege escalation vulnerability that exists due to improper input validation. An attacker with local access could use this vulnerability to modify the file system as root.

CVE-2018-25145
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway Configuration Download General
7.1
HIGH
EPSS
0.1%
2018 CWE-552 2 PoCs

Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers to download sensitive system configuration files. Attackers can retrieve configuration files from multiple directories including '/www', '/etc/m_cli/', and '/tmp' to access system passwords and network settings.

CVE-2018-4037
Clean My Mac General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access can use this vulnerability to modify the file system as root.

CVE-2018-25142
NovaPACS Diagnostics Viewer General
7.1
HIGH
EPSS
0.1%
2018 CWE-611 2 PoCs

NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.

CVE-2018-4050
GOG Galaxy General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can globally adjust folder permissions leading to execution of arbitrary code with elevated privileges.

CVE-2022-0587
librenms/librenms General
7.1
HIGH
EPSS
0.0%
2022 CWE-285 1 PoC

Improper Authorization in Packagist librenms/librenms prior to 22.2.0.

CVE-2022-4504
openemr/openemr General
7.1
HIGH
EPSS
0.4%
2022 CWE-20 1 PoC

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2.

CVE-2022-23400
ImageGear General
7.1
HIGH
EPSS
0.3%
2022 CWE-193 1 PoC

A stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft ImageGear 19.10. A specially-crafted PSD file can overflow a stack buffer, which could either lead to denial of service or, depending on the application, to an information leak. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-39909
Samsung Gear IconX PC Manager General
7.1
HIGH
EPSS
0.0%
2022 CWE-345 1 PoC

Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link.

CVE-2022-0896
microweber/microweber General
7.1
HIGH
EPSS
1.0%
2022 CWE-1336 1 PoC

Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-50799
Fetch Softworks Fetch FTP Client General
7.1
HIGH
EPSS
0.1%
2022 CWE-770 2 PoCs

Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption by sending long server responses. Attackers can send specially crafted FTP server responses exceeding 2K bytes to cause excessive resource utilization and potentially crash the application.

CVE-2022-0436
gruntjs/grunt General
7.1
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.

CVE-2022-29458
Software Genérico General
7.1
HIGH
EPSS
0.0%
2022 3 PoCs

ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

CVE-2022-0630
mruby/mruby General
7.1
HIGH
EPSS
0.2%
2022 CWE-125 1 PoC

Out-of-bounds Read in Homebrew mruby prior to 3.2.

CVE-2022-50950
Webile General
7.1
HIGH
EPSS
1.3%
2022 CWE-22 1 PoC

Webile 1.0.1 contains a directory traversal vulnerability that allows remote attackers to manipulate file system paths without authentication. Attackers can exploit path manipulation to access sensitive system directories and potentially compromise the mobile device's local file system.

CVE-2022-39880
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code execution.

CVE-2022-42280
NVIDIA DGX servers General
7.1
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path traversal, which may lead to authentication bypass.

CVE-2022-42946
Autodesk Maya General
7.1
HIGH
EPSS
0.1%
2022 1 PoC

Parsing a maliciously crafted X_B and PRT file can force Autodesk Maya 2023 and 2022 to read beyond allocated buffer. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVE-2022-0588
librenms/librenms General
7.1
HIGH
EPSS
0.0%
2022 CWE-862 1 PoC

Missing Authorization in Packagist librenms/librenms prior to 22.2.0.